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REMARKS/ARGUMENTS 

Prior to the entry of this Amendment, claims 1-52 were pending in this 
application. No claims are canceled and no new claims are added herein. Therefore, claims 1-52 
remain pending. Claims 24 and 45 have been amended herein to correct typographical errors 
unintentionally introduced in the previous Amendment filed September 13, 2005. Applicants 
respectfully submit that no new matter is present by these amendments and that the amendments 
are made to correct formal matters only to place the claims in better form for appeal. Therefore, 
applicants request entry of the amendments and reconsideration of these claims for at least the 
reasons presented below. 

35 U.S.C. $ 102 Rejection, Patel 

The Office Action has rejected claims 1-52 under 35 U.S.C. § 102(e) as being 
anticipated by U. S. Patent No. 6,438,690 Bl to Patel et al. (hereinafter "Patel"). The Applicant 
respectfully submits the following arguments pointing out significant differences between claims 
1 -52 submitted by the Applicant and Patel. 

"A claim is anticipated only if each and every element as set forth in the claim is 
found, either expressly or inherently described, in a single prior art reference." MPEP 2131 
citing Verdegaal Bros. v. Union Oil Co. of California, 814 F.2d 628, 631, 2 USPQ2d 1051, 1053 
(Fed. Cir. 1987): Applicants respectfully argue that Patel fails to disclose each and every 
claimed element. For example, Patel fails to disclose, either expressly or inherently, retrieving a 
workflow for responding to a request from a set of workflows, wherein the workflow 
corresponds to a set of characteristics for the user. Furthermore, Patel does not disclose 
retrieving a workflow for responding to a request from a set of workflows, wherein the workflow 
corresponds to a set of characteristics for the user including a user type. 
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Patel relates to "a secure end-to-end communication system using [Public Key 
Infrastructure (PKI)] for conducting electronic commerce." (Col. 3, lines 34-35) Under Patel, 
"the system includes web based [Registration Authorities (RAs)] and end users coupled to a 
vault controller." (Gol. 3, lines 35-37) "The controller includes a registration application which 
includes an enrollment component which provides web pages and functions that implement a 
vault based process of applying and receiving a digital certificate by an end user." (Col. 3, lines 
37-41) Patel discloses a method in which "a user submits an enrollment form to the vault 
controller requesting a certificate." (Col. 3, lines 51-53) The form is validated in the registration 
application by the enrollment component which in turn submits the approved form to the master 
registration component for creation of an application for a certificate for the end user. (Col. 3, 
lines 54-59) "The RA reviews each registration request. As part of the review, the RA may need 
to perform additional verification of the applicant's request as determined by an organization's 
policy." (Col. 5, lines 5-8) That is, the registration authority may perform different verification 
procedures depending upon the requirements of the organization for which the certificate is 
being issued, i.e., "the customer." However, Patel does not disclose retrieving a workflow for 
responding to a request from a set of workflows, wherein the workflow corresponds to a set of 
characteristics for the end user. Furthermore, Patel does not disclose retrieving a workflow for 
responding to a request from a set of workflows, wherein the workflow corresponds to a set of 
characteristics for the user including a user type. 

As support for the argument that Patel does in fact teach such elements, the Office 

Action states: 

"Patel discloses how one of his objectives is 'master registration applications including 
policy exit components for customizing registration application behavior consistent with 
customer requirements' (col. 3 lines 25-27) and discloses ? a variety of enrollment 
approaches' all of which are 'easily customized to meet specific customer requirements 
in areas that include content and appearance' (col. 6 lines 14-17). Conversely, as part of 
the RA review 'the RA may need to perform additional verification of the applicant's 
request as determined by an organization's policy' (col. 5 lines 5-8). However, in the 
majority of cases, the RA has no function as the majority of decisions in regards to 
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approving, rejecting, and renewing certificates is automated according to the policy exits 
set by the customer in conjunction with those set by the system and the core business 
rules embodied in the processes which govern certificate issuance (col. 7 lines 3-8, 20-24; 
col. 8 lines 8-26). " [emphasis added] 

This is wholly consistent with the Applicants understanding of Patel as outlined above. 
Specifically, the registration authority may perform different verification procedures depending 
upon the requirements of the organization for which the certificate is being issued, i.e., "the 
customer." In other words, if an end user wants a certificate for interacting with Company X, 
that user is handled based a policy selected by Company X, not selected by or based on the user. 

The Office Action goes on to argue that: 

"Patel provides the situation in which the incoming requests are broken up according to 
the last name of the person applying for the application, and from there is decided which 
RA administrator would decide whether or not to grant the user's request (col. 8 line 48- 
58). 

However, rather than disclosing the selection of a policy or workflow based on a 
user characteristic, this section of Patel actually relates to a manual handling of requests by an 
administrator after a request has failed the automatic process described above. Therefore, this 
section of Patel cannot reasonably be relied upon to show a teaching of retrieving a workflow for 
responding to a request from a set of workflows, wherein the workflow corresponds to a set of 
characteristics for the end user or retrieving a workflow for responding to a request from a set of 
workflows, wherein the workflow corresponds to a set of characteristics for the user including a 
user type. 

Further attempting to demonstrate such a teaching in Patel, the Office Action goes 
on to argue that: 

"In order to partition the applications into domains under different RAs, Patel utilizes the 
information collected from the user with the request for the certificate including 
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information about the end user, characteristics such as the beginning initial of their last 
name for example (col. 3 lines 49-51). Distinctions are also made between this users who 
can use the default enrollment approaches and those who require a custom approach, 
those of the first type are sent into the vault registration application enrollment facilities, 
and those of the second type are routed past the facilities in order to work directly with 
the RAs (col. 6 lines 44-51) where the security of the overall process is determined by the 
strength of the customer's implementation of the vault registration application (col. 6 
lines 51-55)." 

However, col. 3, lines 49-51 actually state "a database component stores and 
retrieves information about end user applicants, certificate requests, and their processing." This 
section makes no reference to utilizing characteristics of the user, such as the beginning initial of 
their last name, to retrieve a workflow for responding to a request. Rather, as discussed above, 
Patel teaches using the first initial of the user's last name to divide failed request between 
administrators for manual review of the requests, including review of information saved in the 
database component and related to that failed request. (Col. 8, line 8 - col. 9, line 22) 
Furthermore, any distinctions made by Patel between users who can use the default enrollment 
approaches and those who require a custom approach is based on the enrollment approach 
specified by the customer for which the user is requesting a certificate, not based on 
characteristics of the user. In other words and as stated above, under Patel, if an end user wants a 
certificate for interacting with Company X, that user is handled based a policy selected by 
Company X, not selected by or based on the user. 

Therefore, the Applicants respectfully but strongly disagree with the argument 
that Patel discloses retrieving a workflow for responding to a request from a set of workflows, 
wherein the workflow corresponds to a set of characteristics for the end user or retrieving a 
workflow for responding to a request from a set of workflows, wherein the workflow 
corresponds to a set of characteristics for the user including a user type.* Rather, under Patel, the 
registration authority may perform different verification procedures depending ONLY .upon the 
requirements of the organization or customer for which the certificate is being issued. 
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Claim 1, upon which claims 2-15 depend, claim 16, upon which claims 17-26 
depend, and claim 27, upon which claims 28-37 depend, each recite in part "receiving a request 
for a certificate related action for a user; and retrieving a workflow for responding to said request 
from a set of workflows, wherein said workflow corresponds to said certificate related action and 
a set of characteristics for said user including a user type." Patel does not disclose retrieving a 
workflow for responding to a request from a set of workflows, wherein the workflow 
corresponds to a set of characteristics for the user including a user type. Rather, under Patel, the 
registration authority may perform different verification procedures depending ONLY upon the 
requirements of the organization for which the certificate is being issued, not a set of 
characteristics for the user or the type of user. For at least these reasons, claims 1-37 are 
distinguishable from Patel and should be allowed. 

Claim 38, upon which claims 39-42 depend, claim 43, upon which claims 44-47 
depend, and claim 48, upon which claims 49-52 depend, each recite in part "receiving a request 
for a certificate related action for a user; and retrieving a workflow for responding to said request 
from a set of workflows, wherein said workflow corresponds to said certificate related action and 
a set of characteristics for said user, wherein said set of workflows includes a plurality of 
workflows for responding to said certificate related action, and wherein each workflow in said 
plurality of workflows corresponds to a different set of characteristics for a user." Patel does not 
disclose retrieving a workflow for responding to a request wherein the workflow corresponds to 
a set of characteristics for the user and each workflow corresponds to a different set of 
characteristics for the user. Rather, under Patel, the registration authority may perform different 
verification procedures depending ONLY upon the requirements of the organization for which 
the certificate is being issued, not a set of characteristics for the user. For at least these reasons, 
claims 1-37 are distinguishable from Patel and should be allowed. 
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In view of the foregoing, Applicants believe all claims now pending in this 



Application are in condition for allowance and an action to that end is respectfully requested; 



If the Examiner believes a telephone conference would expedite prosecution of 



this application, please telephone the undersigned at 303-571-4000. 



TOWNSEND and TOWNSEND and CREW LLP 
Two Embarcadero Center, Eighth Floor 
San Francisco, California 941 1 1-3834 
Tel: 303-571-4000 
Fax: 303-571-4321 

WJD:sbm 

60679493 v1 



CONCLUSION 




William J. Daley 
Reg. No. 52,471 
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